Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

services/luci/entrypoint.sh

Raw
#!/usr/bin/env bash
set -euo pipefail

sshd_config=/run/luci-sshd.conf
ssh_command=/run/luci-ssh-command

write_sshd_config() {
  local name value escaped
  cat >"${sshd_config}" <<'SSHD_CONFIG'
Port 2223
HostKey /data/ci/ssh/ssh_host_ed25519_key
PasswordAuthentication no
KbdInteractiveAuthentication no
AuthenticationMethods publickey
PermitRootLogin prohibit-password
AuthorizedKeysFile /data/ci/authorized_keys
ForceCommand /run/luci-ssh-command
DisableForwarding yes
AllowTcpForwarding no
X11Forwarding no
PermitTTY no
SSHD_CONFIG

  printf '%s\n' '#!/usr/bin/env bash' >"${ssh_command}"
  for name in \
    LUCI_DATA_DIR \
    LUCI_REPO_ROOTS \
    LUCI_HTTP_ADDR \
    LUCI_BASE_URL \
    LUCI_INBOX_DIR \
    LUCI_PODMAN_SOCKET \
    LUCI_SSH_ADDR \
    LUCI_SSH_AUTHORIZED_KEYS \
    LUCI_THEME_CSS \
    LUCI_DEFAULT_TIMEOUT \
    LUCI_DEFAULT_MEMORY \
    LUCI_DEFAULT_CPUS \
    LUCI_CACHE_MAX_VERSIONS \
    LUCI_CACHE_MAX_BYTES \
    LUCI_LOG_LEVEL \
    LUCI_PUBLISH_REGISTRY_AUTH_FILE \
    LUCI_PUBLISH_PKG_ROOT \
    LUCI_PUBLISH_SITE_ROOT; do
    value="${!name:-}"
    [[ -n "${value}" ]] || continue
    [[ "${value}" != *$'\n'* && "${value}" != *$'\r'* ]] || {
      echo "invalid newline in ${name}" >&2
      exit 1
    }
    escaped="${value//\\/\\\\}"
    escaped="${escaped//\"/\\\"}"
    printf 'SetEnv %s="%s"\n' "${name}" "${escaped}" >>"${sshd_config}"
    printf 'export %s=%q\n' "${name}" "${value}" >>"${ssh_command}"
  done
  printf '%s\n' 'exec /usr/local/bin/luci ssh' >>"${ssh_command}"
  chmod 0755 "${ssh_command}"
}

stop_children() {
  kill "${sshd_pid:-}" "${luci_pid:-}" 2>/dev/null || true
  wait "${sshd_pid:-}" "${luci_pid:-}" 2>/dev/null || true
}

trap 'stop_children; exit 0' INT TERM

install -d -m 0700 /data/ci/ssh /run/sshd
if [[ ! -f /data/ci/ssh/ssh_host_ed25519_key ]]; then
  ssh-keygen -q -t ed25519 -N '' -f /data/ci/ssh/ssh_host_ed25519_key
fi
/usr/local/bin/luci env-check
write_sshd_config
/usr/sbin/sshd -t -f "${sshd_config}"

/usr/sbin/sshd -D -e -f "${sshd_config}" &
sshd_pid=$!
/usr/local/bin/luci serve &
luci_pid=$!

set +e
wait -n "${sshd_pid}" "${luci_pid}"
status=$?
set -e
stop_children
exit "${status}"